#SlackBot
Malware/Tool
2019-11-12 • HWP + SlackBot Malware Analysis
SlackBot is a Windows loader observed in malicious HWP documents whose embedded PostScript created and launched update.exe in the user's Startup folder. On execution, the loader created a mutex, decrypted HTTP header material, and used Slack's public API to retrieve an additional binary. It XOR-decrypted the downloaded payload with the same documented key and executed it in memory, making the sample a staged downloader and memory loader rather than a fully described standalone backdoor. Two differently named and themed HWP samples found on VirusTotal contained the same PostScript, suggesting separate lures may have delivered the same chain.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days